Privacy Policy

T&T Zimmervermietung Oßmaritz GbR · www.monteurzimmer-bei-jena.de · Version: August 2026

This English version is provided for your convenience. In the event of any discrepancy, the German version („Datenschutzerklärung“) is authoritative.

We take the protection of your personal data seriously. Below we explain which personal data we process when you visit our website, contact us, make a booking and stay at our accommodation, for what purposes we do so, and what rights you have.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection laws is:

T&T Zimmervermietung Oßmaritz GbR represented by its partners Tina Grätscher and Tony Grätscher Talweg 14 07639 Bad Klosterlausnitz Germany

Phone: +49 171 7720722 Fax: +49 36601 935658 E-mail: info@monteurzimmer-bei-jena.de

For questions regarding data protection, please contact: datenschutz@monteurzimmer-bei-jena.de

We are not legally required to appoint a data protection officer and have not done so.

2. Your rights as a data subject

With regard to the personal data concerning you, you have the following rights against us:

  • Access to the data stored about you and its processing (Art. 15 GDPR),
  • Rectification of inaccurate or incomplete data (Art. 16 GDPR),
  • Erasure of your data, unless statutory retention obligations prevent this (Art. 17 GDPR),
  • Restriction of processing (Art. 18 GDPR),
  • Data portability, where processing is based on consent or a contract and is carried out by automated means (Art. 20 GDPR),
  • Objection to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR, see Section 10).

You may withdraw any consent you have given at any time with effect for the future (Art. 7(3) GDPR). The lawfulness of processing carried out before the withdrawal remains unaffected.

To exercise your rights, an informal message to the contact details above is sufficient.

Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The supervisory authority responsible for us is:

Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (TLfDI) Häßlerstraße 8 99096 Erfurt, Germany www.tlfdi.de

You may also contact the supervisory authority of your place of residence. An overview is available at: https://www.bfdi.bund.de/DE/Service/Anschriften/anschriften_table-node.html

3. General information on legal bases, recipients and retention periods

Unless otherwise stated below, the following applies:

Legal bases: We process personal data on the basis of

  • Art. 6(1)(a) GDPR (consent),
  • Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures),
  • Art. 6(1)(c) GDPR (legal obligation, e.g. German Federal Registration Act (BMG), German Fiscal Code (AO), German Commercial Code (HGB)),
  • Art. 6(1)(f) GDPR (legitimate interest).

Recipients: Within our company, only those persons who need your data to perform their tasks have access to it. In addition, data may be transferred to the following categories of recipients to the extent described in the respective section: tax advisors and accounting, credit institutions (payment processing), registration authorities and other public authorities where legally required, lawyers and debt collection agencies for the enforcement of claims, credit agencies (credit checks), cleaning and maintenance contractors (only to the extent required for service provision, e.g. room number and occupancy period), and operators of booking platforms through which you have booked.

Hosting: We operate our website and e-mail systems on our own servers in a data centre within the European Union. Data is not passed on to external hosting providers, with the exception of the Google service described in Section 8.

Retention period: We store personal data only for as long as necessary for the respective purpose or as required by statutory retention obligations. Booking and invoicing records are subject to the retention periods under German commercial and tax law (currently 8 years for accounting documents and 10 years for books, annual accounts and invoices under Section 147 AO / Section 257 HGB). After expiry of these periods, the data is deleted unless a longer retention is required for the establishment, exercise or defence of legal claims.

4. Visiting our website

4.1 Server log files

Nature and purpose: When you access our website, our server automatically records technical information: IP address, date and time of access, page or file requested, amount of data transferred, HTTP status code, browser type and version, operating system and the previously visited page (referrer). This data is not combined with other data sources and is not analysed to identify individual visitors. We reserve the right to review the log files retrospectively if there are concrete indications of unlawful use or an attack on our systems.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the technical provision, stability and security of our website and in the prevention and investigation of attacks.

Retention period: Log files are deleted after 90 days at the latest. In the event of security-relevant incidents (e.g. attacks), the relevant entries are retained until the incident has been fully investigated.

Provision: Provision is neither required by law nor by contract; however, the website cannot technically be accessed without an IP address.

4.2 SSL/TLS encryption

Our website uses SSL/TLS encryption to protect the transmission of confidential content (e.g. enquiries submitted via the contact form). You can recognise an encrypted connection by „https://“ in the address bar and the padlock symbol in your browser. Data you transmit to us in encrypted form cannot be read by third parties.

4.3 Cookies and consent management (consent tool)

Nature and purpose: Cookies are small text files stored on your device when you visit a website. We use

  • technically necessary cookies that are required for the operation of the website (e.g. to store your cookie settings), and
  • cookies and similar technologies requiring consent for Google Analytics (see Section 8), which are only set if you have given your consent in our consent tool.

On your first visit, a consent banner is displayed allowing you to individually enable or reject services that require consent. You can change or withdraw your selection at any time via the „Cookie settings“ link in the website footer. An overview of the cookies used, including provider, purpose and storage period, can be found in the cookie settings.

Legal basis: For technically necessary cookies, Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) in conjunction with Art. 6(1)(f) GDPR (legitimate interest in a functioning website); the storage of your consent decision is based on Art. 6(1)(c) GDPR (obligation to demonstrate consent under Art. 7(1) GDPR). For all other cookies, Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR (consent).

Retention period: The cookie storing your consent decision is kept for 12 months. The storage period of the other cookies can be found in the cookie settings.

You can additionally delete or block cookies via your browser settings. Please note that individual functions of the website may be restricted in this case.

5. Contacting us

5.1 Contact form, e-mail, telephone and fax

Nature and purpose: If you contact us via the contact form, by e-mail, telephone or fax, we process the data you provide (in particular name, e-mail address, telephone number, content of your enquiry) as well as the date and time of the enquiry in order to process and respond to it. When using the contact form, your IP address is also stored so that misuse can be traced. E-mails are processed on our own mail servers; the usual technical connection data (sender, recipient, time, servers involved) is generated in the process.

Booking enquiries via t-und-t-gbr.de: The general contact form on this website transmits your entries directly to our e-mail inbox. For specific room enquiries, clicking the „Enquiry“ button redirects you to our second website www.t-und-t-gbr.de, where the enquiry form is provided. That website is operated by T&T Vermietung GbR, Talweg 14, 07639 Bad Klosterlausnitz, Germany – a sister company with the same partners and the same address, which is independently responsible under data protection law for that website and its enquiry form and operates them on the same own servers. No personal data is transferred during the redirect; you only enter your data there. T&T Vermietung GbR forwards your enquiry to us so that we can prepare a quotation for you (Art. 6(1)(b) GDPR); from that point on, we process your data as described in this policy. The privacy policy published on www.t-und-t-gbr.de applies to the collection of data on that website; Google Analytics is not used there.

Legal basis: If your enquiry relates to a booking or a quotation, the legal basis is Art. 6(1)(b) GDPR (pre-contractual measures or performance of a contract). Otherwise, Art. 6(1)(f) GDPR; our legitimate interest lies in the proper processing of and response to enquiries.

Retention period: Enquiries that do not result in a contract are deleted no later than 12 months after final processing. If a contract is concluded, the retention periods under Section 3 apply.

Provision: Providing your data is voluntary. However, we can only respond to your enquiry if you provide the information required for processing (at least one means of contact and the reason for the enquiry).

5.2 Communication via WhatsApp

Nature and purpose: We additionally offer you the option of contacting us via the WhatsApp messenger (provider: WhatsApp Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, part of the Meta group of companies). If you write to us via WhatsApp, we process your telephone number, your profile name and the content of the communication in order to handle your enquiry. Use of WhatsApp is voluntary; you can equally address all matters to us by e-mail or telephone.

Note: WhatsApp processes metadata (e.g. telephone numbers, time of communication, device information) under its own responsibility and may transfer it to servers in the USA; this is done on the basis of the European Commission’s adequacy decision for the EU-US Data Privacy Framework, to which Meta Platforms, Inc. has subscribed. Further information can be found in WhatsApp’s privacy policy: https://www.whatsapp.com/legal/privacy-policy-eea. Message contents are end-to-end encrypted. Please do not transmit particularly sensitive data (e.g. copies of ID documents) via WhatsApp; use e-mail or present them on arrival instead.

Legal basis: Art. 6(1)(b) GDPR (enquiries regarding bookings and ongoing contracts) or Art. 6(1)(f) GDPR (legitimate interest in fast and uncomplicated communication with guests, in particular during their stay).

Retention period: As under 5.1. Chat histories relating to completed matters are deleted no later than 12 months after completion, unless retention obligations apply.

6. Booking, contract processing and stay

6.1 Quotation, booking and contract processing

Nature and purpose: To prepare a quotation and to conclude and perform the rental contract, we process the following data of the client and the guests: name, address, contact details (telephone, e-mail), for companies additionally company name, contact person and, where applicable, VAT identification number, booking data (room, period, number of persons, price, special arrangements), invoicing and payment data, and the correspondence arising in the course of contract performance. For bookings by companies or agents, we receive the data of the accommodated persons (name, contact details, period of stay, role as main contact person) from the client. Contract performance also includes transmitting the access code, documenting handovers (check-in and handover reports including photographs of the premises), handling the deposit, damages and complaints, and communication during the stay.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures). Where we process data of accommodated persons who are not themselves contracting parties, processing is based on Art. 6(1)(f) GDPR; our legitimate interest lies in the proper performance of the contract with the client, safety on the premises and the allocation of contact persons. Processing to fulfil tax and commercial law obligations is based on Art. 6(1)(c) GDPR.

Recipients: Tax advisors/accounting; our bank for payment processing; cleaning staff and tradespeople to the extent they require occupancy information; in the event of payment default or disputes, lawyers, debt collection agencies and courts.

Retention period: For the duration of the contractual relationship and thereafter in accordance with the statutory retention periods (Section 3). Handover reports and photographs are retained until the deposit and any damage claims have been fully settled, at the latest until expiry of the civil-law limitation periods.

Provision: Provision of the data is required for concluding the contract. Without it, we cannot process a booking.

6.2 Registration requirements and guest list

Nature and purpose: Under the German Federal Registration Act (BMG), we are obliged to keep a registration form („Meldeschein“) for guests of foreign nationality (Sections 29, 30 BMG). For this purpose we record: date of arrival and expected departure, surname, first name, date of birth, nationality, address, and the type, number and issuing authority of the identity document. The guest must sign the registration form personally and present a valid identity document to us. From guests of German nationality, we collect name, address, contact details and period of stay for the purposes of fire safety, security on the premises and contract performance. We maintain an occupancy list so that the number and identity of persons in the building is known in an emergency (e.g. fire, evacuation).

For stays exceeding the periods under Section 27(2) BMG, we issue the landlord’s confirmation („Wohnungsgeberbestätigung“) under Section 19 BMG in our capacity as the accommodation provider; for this purpose we process the information required therein.

Legal basis: Art. 6(1)(c) GDPR in conjunction with Sections 19, 29, 30 BMG (legal obligation); for the occupancy list and the data of German guests, Art. 6(1)(b) and (f) GDPR (legitimate interest in fire safety and security).

Recipients: Registration forms are handed over on request to the competent registration authority, police and regulatory authorities and other bodies entitled under Section 30(3) BMG. No other disclosure takes place.

Retention period: In accordance with Section 30(4) BMG, we retain registration forms for one year from the date of arrival and destroy them no later than three months after expiry of this period. Copies of ID documents voluntarily sent to us in advance are deleted immediately after the required details have been recorded. The occupancy list is updated after departure; the data remains part of the contract data (Section 6.1).

Provision: Providing registration data is required by law for foreign guests and required by contract for all other guests. Accommodation is not possible without this information.

6.3 Credit check

Nature and purpose: To protect ourselves against payment defaults, we check information on the previous payment behaviour of the contracting party for bookings by companies and for long-term bookings with payment on invoice or in monthly instalments, both before conclusion of the contract and – where there is a legitimate interest, for example in the event of payment default or a substantial extension of the order – during the ongoing contractual relationship. For this purpose we cooperate with infoscore Consumer Data GmbH, Rheinstraße 99, 76532 Baden-Baden, Germany, from which we obtain the required credit information. To this end, we transmit your name (for companies: company name and address), your address and – for natural persons – your date of birth to infoscore Consumer Data GmbH. The credit agency uses mathematical-statistical methods to calculate a probability value (score) regarding creditworthiness. No credit check is carried out for bookings with full advance payment of the total price.

We do not make the decision on the conclusion of the contract or the payment terms (e.g. advance payment instead of invoice, amount of the deposit) solely by automated means; the result of the credit check is one criterion among several and is assessed by us personally. If the result is negative, we generally offer the booking against advance payment.

Legal basis: Art. 6(1)(b) GDPR (decision on the conclusion of the contract and the payment terms) and Art. 6(1)(f) GDPR; our legitimate interest lies in protection against bad debts for services we provide before full payment. The transfer to the credit agency and its processing are also carried out in compliance with Section 31 of the German Federal Data Protection Act (BDSG).

Recipient: infoscore Consumer Data GmbH, Rheinstraße 99, 76532 Baden-Baden, Germany. The information pursuant to Art. 14 GDPR on data processing at infoscore Consumer Data GmbH can be found at: https://www.experian.de/icd-infoblatt

Retention period: We store the result of the credit check for the duration of the contractual relationship and for no longer than 12 months after its termination, provided no claims are outstanding.

Provision: The credit check is a prerequisite for booking on invoice or in instalments. If you object to the check, a booking is only possible against full advance payment.

6.4 Bookings via external platforms

Nature and purpose: If you book via a booking platform (e.g. Booking.com B.V., Oosterdoksstraat 163, 1011 DL Amsterdam, Netherlands; Airbnb Ireland UC, 8 Hanover Quay, Dublin 2, Ireland), we receive from the platform the data required to process the booking (name, contact details, booking period, number of persons, price, payment status where applicable). We transmit to the platform the information required for processing (e.g. confirmation of arrival and departure, cancellations, review requests). The platforms are independently responsible for processing your data in connection with the booking; their privacy policies apply.

Legal basis: Art. 6(1)(b) GDPR.

Retention period: As under 6.1.

6.5 Payment processing

Payments are made by bank transfer to our business account. In doing so, we process the data customary in payment transactions (name of the account holder, IBAN, amount, payment reference), which we need to allocate the payment and for bookkeeping. For platform bookings, payment may be processed via the platform or its payment service provider in accordance with its privacy policy. The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR (bookkeeping obligations). Recipients are our bank and our tax advisor. The retention period is governed by Section 3.

6.6 Guest Wi-Fi

Nature and purpose: We provide our guests with internet access (Wi-Fi) during their stay. For provision, troubleshooting and prevention of misuse, our network system processes technical connection data of your device (MAC address, assigned internal IP address, time and duration of the connection, amount of data transferred). We do not analyse or store the content of your communication or the websites you visit. To protect the network and other guests, certain services, ports or websites may be blocked.

Legal basis: Art. 6(1)(b) GDPR (provision of Wi-Fi as an ancillary contractual service) and Art. 6(1)(f) GDPR; our legitimate interest lies in the security and functionality of the network and in being able to attribute the connection in the event of official requests or third-party claims (e.g. copyright infringements).

Retention period: Connection data is deleted after 30 days at the latest, unless it is needed for longer to investigate a specific security incident or to defend against claims.

6.7 Enforcement of and defence against claims

Where necessary, we process your data for the establishment, exercise or defence of legal claims (e.g. in the event of payment default, damage to the rental property, breaches of the house rules). The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in enforcing our contractual and statutory rights. Recipients may include lawyers, debt collection agencies, courts, insurers and – in the case of criminal offences – police and law enforcement authorities. The data is stored until the respective matter is concluded or until expiry of the limitation periods.

7. Disclosure to public authorities

We disclose personal data to public authorities (e.g. registration authorities, police, customs, tax authorities, regulatory offices) only where we are legally obliged to do so or where an official request for information exists on a statutory basis. The legal basis is Art. 6(1)(c) GDPR.

8. Web analytics and form protection

8.1 Google Analytics 4

We use the Google Analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland („Google“). The service is only loaded if you have given your consent via our consent tool. Without consent, no data is transmitted to Google.

Transfer to third countries: When Google Analytics is used, personal data may be transferred to servers of Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework, for which an adequacy decision of the European Commission under Art. 45 GDPR exists. In addition, we have agreed the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR) with Google. Further information: https://business.safety.google/privacy/

Nature and purpose: We use Google Analytics to statistically evaluate the use of our website (e.g. visitor numbers, pages viewed, time spent, approximate region of origin, devices and browsers used) and to improve our offering. For this purpose, Google Analytics uses cookies or comparable technologies and processes a pseudonymous user ID, device and browser information, the truncated IP address (in Google Analytics 4, IP addresses are not stored but only used for rough geographical allocation and then discarded), referrer and interactions on the website. We have deactivated the functions for advertising and personalisation purposes (Google Signals, ads personalisation) and do not link the analytics data with other Google accounts. A data processing agreement under Art. 28 GDPR is in place with Google.

Legal basis: Your consent, Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. You may withdraw your consent at any time via the cookie settings with effect for the future.

Retention period: User- and event-related data stored in Google Analytics is automatically deleted after 14 months. Aggregated statistics without personal reference remain unaffected.

Further information: https://policies.google.com/privacy and https://support.google.com/analytics/answer/6004245. You can additionally prevent data collection by Google Analytics using the browser opt-out add-on: https://tools.google.com/dlpage/gaoptout

8.2 Protection of the contact forms (ALTCHA)

Nature and purpose: To protect our forms (the general contact form on this website and the enquiry form on www.t-und-t-gbr.de, operated by our sister company, see Section 5.1) against automated submissions (spam, bots, abusive harvesting of data), we use the open-source ALTCHA method, which is operated entirely on our own servers. Before a form is submitted, your browser solves a small cryptographic computational task (proof of work) in the background, the result of which is verified by our server. No cookies are set, no behavioural data or device characteristics are analysed (no fingerprinting), and no data is transmitted to third parties. Only the technically required connection data (IP address, time) and the verification result are processed. The verification is a prerequisite for submitting a form; it runs without any action on your part. In addition, we use server-side measures against mass requests (rate limiting).

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our forms and systems against misuse, spam and automated attacks, and in protecting the data of other users submitted via the forms. Access to your device is strictly necessary under Section 25(2) no. 2 TDDDG for the function you have requested (submitting an enquiry); consent is therefore not required.

Recipients: None. Processing takes place exclusively on our own servers.

Retention period: Verification data is deleted after the enquiry has been processed, at the latest after 7 days. Further information on ALTCHA: https://altcha.org

9. No other third-party services

Our website does not use social media plugins, external fonts (web fonts are loaded locally from our server), embedded map or video services, or any other services that transmit data to third-party servers. The form protection (Section 8.2) and our sister company’s website www.t-und-t-gbr.de, which hosts the enquiry form for room bookings, run entirely on our own servers. The only exception is Google Analytics (Section 8.1), which is loaded only with your consent.

10. Your right to object under Art. 21 GDPR

Right to object on grounds relating to your particular situation: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(f) GDPR (balancing of interests). This also applies to profiling based on that provision.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Recipient of an objection: T&T Zimmervermietung Oßmaritz GbR Talweg 14, 07639 Bad Klosterlausnitz, Germany E-mail: datenschutz@monteurzimmer-bei-jena.de

We do not carry out direct marketing (and therefore no right to object under Art. 21(2) GDPR arises).

11. Automated decision-making

No automated individual decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. The result of the credit check (Section 6.3) is taken into account in our decision but is always assessed by us personally.

12. Data security

We implement technical and organisational measures under Art. 32 GDPR to protect your data against loss, manipulation and unauthorised access. These include in particular encrypted transmission (TLS), operation of our systems on our own servers in the EU, access restrictions, regular backups and keeping the software we use up to date. Registration forms and contract documents in paper form are kept locked away.

13. Changes to this privacy policy

We reserve the right to amend this privacy policy so that it always complies with current legal requirements or to reflect changes to our services (e.g. when introducing new services). The version published on our website at the time applies. For existing contractual relationships, we will inform you of material changes in text form.

14. Questions about data protection

If you have any questions about data protection or wish to exercise your rights, please contact: datenschutz@monteurzimmer-bei-jena.de or the contact details given in Section 1.